Fault injection attacks on emerging non-volatile memory and countermeasures

Fault injection attacks on emerging non-volatile memory and countermeasures
复制标题

新兴非易失性存储器的故障注入攻击及对策

DOI:
10.1145/3214292.3214302
复制
发表时间:
2018
期刊:
International Workshop on Hardware and Architectural Support for Security and Privacy
影响因子:
--
通讯作者:
Ghosh, Swaroop
Ghosh, Swaroop
中科院分区:
--
文献类型:
--
作者:
Khan, Mohammad Nasim;Ghosh, Swaroop

文献摘要

参考文献

被引文献

相似文献

新兴的非易失性存储器 (NVM) 面临高且不对称的读/写电流和长写入延迟的问题,这可能导致电源电压下降和接地反弹等电源噪声。电源噪声的大小取决于旧数据和正在写入的新数据(对于写操作)或存储的数据(对于读操作)。在本文中,我们表明对手可以在其内存空间中写入特定的数据模式(导致确定性电源噪声)以发起 i)拒绝服务(DoS)攻击(完全写入失败),以及 ii)在与对手的内存空间共享相同电源轨的受害者内存空间中进行特定极性故障(即故障注入)攻击。如果未在逐位工艺变化下以及指定(-10°C 至 90°C)和未指定温度范围(即小于 -10°C 和大于 90°C)下对存储器的所有模式、所有可能的位置组合、所有可能的并行读/写条件进行详尽测试,则这些攻击是特别可能的。仿真结果表明,攻击者可以通过向受害者的写入位置注入超过 120mV 的电源噪声来对受害者的写入操作发起 DoS 攻击。攻击者还可以通过向受害者的写入位置注入大于 50mV 但小于 120mV 的电源噪声,对受害者的写入操作发起 0 → 1 极性故障注入攻击。此外,攻击者可以通过向受害者的读取位置注入超过 150mV 的电源噪声来导致数据“1”读取失败。
Emerging Non-Volatile Memories (NVMs) suffer from high and asymmetric read/write current and long write latency which can result in supply noise such as supply voltage droop and ground bounce. The magnitude of supply noise depends on the old data and the new data that is being written (for write operation) or on the stored data (for read operation). In this paper, we show that the adversary can write specific data pattern (that results in deterministic supply noise) in their memory space to launch, i) Denial of Service (DoS) attack (total write failure), and ii) specific polarity fault (i.e., fault injection) attack in victim's memory space sharing the same power rails with the adversary's memory space. These attacks are specifically possible if exhaustive testing of the memory for all patterns, all possible location combinations, all possible parallel read/write conditions are not performed under bit-to-bit process variations and, specified (−10°C to 90°C) and unspecified temperature ranges (i.e., less than -10°C and greater than 90°C). Simulation result indicates that adversary can launch DoS attack on victim's write operation by injecting more than 120mV of supply noise to victim's write location. The adversary can also launch 0 → 1 polarity fault injection attack on victim's write operation by injecting supply noise greater than 50mV but shorter than 120mV to victim's write location. Furthermore, the adversary can cause data '1' read failure by injecting more than 150mV of supply noise to victim's read location.
新兴非易失性存储器的安全性:攻击与防御
DOI: --
发表时间: 2016
期刊: IEEE VLSI Test Symposium
影响因子: --
作者:
Kaveh Shamsi;Yier Jin
通讯作者: Yier Jin
DOI: 10.1007/s13389-017-0165-6
发表时间: 2017-05
影响因子: 1.9
作者:
Sarani Bhattacharya;Debdeep Mukhopadhyay
通讯作者: Sarani Bhattacharya;Debdeep Mukhopadhyay
阻变随机存取存储器(RRAM)的最新进展
DOI: --
发表时间: 2012
期刊: IEEE Silicon Nanoelectronics Workshop
影响因子: --
作者:
Yi Wu;Shimeng Yu;X. Guan;H. Wong
通讯作者: H. Wong
DOI: --
发表时间: 2015
期刊: Design Automation Conference
影响因子: --
作者:
Jaedong Jang;Jongsun Park;Swaroop Ghosh;S. Bhunia
通讯作者: S. Bhunia
STTRAM 的下降缓解末级缓存架构
DOI: --
发表时间: 2017
期刊: Design, Automation and Test in Europe
影响因子: --
作者:
Radha Krishna Aluru;Swaroop Ghosh
通讯作者: Swaroop Ghosh